Since February 2026, multiple incidents involving data theft and extortion have been attributed to activity cluster CL-CRI-1116, also known as BlackFile, UNC6671, and Cordial Spider. These financially-motivated attackers, likely associated with "The Com" collective, employ voice-based phishing combined with credential harvesting through fraudulent login pages. They impersonate IT support staff to steal credentials and bypass multi-factor authentication. The attackers focus on Living Off the Land techniques, abusing legitimate APIs like Microsoft Graph to access SharePoint sites and Salesforce data. They search for confidential information and employee data within SaaS environments, then exfiltrate it through browser downloads or API exports. To pressure victims into paying seven-figure ransoms, attackers send demands via Gmail and compromised email accounts, sometimes employing SWATting tactics against executives.
Targeted Sectors
Executive Summary
The group's activities have resulted in multiple incidents of data theft and extortion, with demands for significant ransoms. Their operations are characterized by a high level of sophistication and adaptability, making them a challenging threat to detect and respond to. As such, organizations in the retail and information technology sectors must remain vigilant and take proactive measures to protect themselves against this and similar threats.
Enhanced Description
In terms of the threat actor's motivations and goals, it is clear that financial gain is the primary driver of their activities. The group's use of extortion and ransom demands is a key aspect of their modus operandi, and they appear to be willing to use a range of tactics to achieve their objectives. This includes the use of SWATting tactics against executives, which creates a sense of urgency and fear, and can put significant pressure on organizations to pay the demanded ransom. The fact that the group is willing to use such tactics highlights the ruthless nature of their operations and the need for organizations to be prepared to respond quickly and effectively in the event of an attack.
Key Capabilities
MITRE ATT&CK Tactics
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is moderate to high, based on multiple reported incidents and technical analysis of the threat actor's tactics, techniques, and procedures (TTPs). However, there may be some uncertainty regarding the group's exact motivations, relationships with other threat actors, and the full scope of their operations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
32
IOCs
0
Observed Data
0
Tactics